note 21430 added to function.md5

From: Date: Mon, 13 May 2002 03:40:38 +0000
Subject: note 21430 added to function.md5
Groups: php.notes 
Request: Send a blank email to php-notes+get-30571@lists.php.net to get a copy of this message
You could store an md5 hash of the pass on server side, then md5 with javascript the entered pass on user side, and finally append/xor in the sessionID on both sides, re-md5 on both sides and compare notes :). Course, even if you do so, the only way to keep a ip-sniffer (who is willing to ip-forge) from then hijacking the session would be to send a random challenge (dual md5-ed with pass hash and stored in $_SESSION), and have a client side frame store the pass md5 and POST the appropriate one-shot hashed response when its ready... But if you're that paranoid you might want to just go full https://... -- http://www.php.net/manual/en/function.md5.php http://master.php.net/manage/user-notes.php?action=edit+21430 http://master.php.net/manage/user-notes.php?action=delete+21430 http://master.php.net/manage/user-notes.php?action=reject+21430

« previous php.notes (#30571) next »